PT-2025-12024 · Dask · Dask
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-10096
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dask versions <=2024.8.2
Description
The issue concerns a vulnerability in the Dask Distributed Server. It allows attackers to craft malicious objects using pickle serialization. These objects can be serialized on the client side and sent to the server for deserialization, potentially leading to remote command execution and granting full control over the Dask server.
Recommendations
For Dask versions <=2024.8.2, consider avoiding the use of pickle serialization until a patch is available. As a temporary workaround, restrict access to the Dask Distributed Server to minimize the risk of exploitation.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dask